{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://data.datagrok.ai/vex/jkg_python/1.1.1.json",
  "author": "Datagrok",
  "timestamp": "2026-09-14T01:06:47Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2024-55459"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "keras 2.15 is the last Keras-2 release; every fix for this advisory is Keras-3-only, and the kernel keeps Keras 2 while efficientnet and tf.keras (Keras-2 API) user scripts depend on it. Exploitation requires the kernel to load an attacker-supplied model/config file — in this image the only actor able to do that is the script author, who already executes arbitrary code in the same kernel process by design (server-side scripting), so no privilege boundary is crossed."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12058"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12060"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-3000"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "torch: memory corruption in torch.jit.script (GHSA-rrmf-rvhw-rf47), patched in 2.13.0. The kernel is held at 2.10 because every conda-forge pytorch from 2.11 up declares 'setuptools <82', which cannot coexist with the setuptools>=83 floor that closes CVE-2026-59890 (MEDIUM 6.1) — the two are mutually exclusive on conda-forge, and this one is LOW (CVSS4 1.9) and local-only. Triggering it means running crafted code through torch.jit.script inside a kernel whose script author already executes arbitrary code in that process by design — same rationale as CVE-2024-55459. Drop this entry and raise the floor once pytorch lifts the setuptools cap. Verified 2026-08-25."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-9906"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-0994"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "python-protobuf is capped <5 by tensorflow 2.15 (kept for the Keras-2 API). The parse-time resource exhaustion can only be triggered by input the script author feeds their own kernel process, which they can already terminate directly; no other principal parses protobuf here."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-11816"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12479"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12480"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12481"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12482"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12484"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12570"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12876"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13608"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-14456"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-14457"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-1462"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18798"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18924"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19931"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54284"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54874"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59893"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59894"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63072"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63073"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63074"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63075"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63076"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-71211"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-71491"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-71513"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-71514"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-75803"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-78680"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-78681"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-78682"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-79657"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-79674"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-79675"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-79676"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80206"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80229"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80230"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80231"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80255"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80256"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-81722"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-81723"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-81724"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-81725"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-81726"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-81727"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-82208"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-82209"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-84305"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9335"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.1"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    }
  ]
}
